Lucene search

K
wpvulndbWpvulndbWPVDB-ID:950F46AE-4476-4969-863A-0E55752953B3
HistoryMay 31, 2021 - 12:00 a.m.

FooGallery < 2.0.35 - Authenticated Stored Cross-Site Scripting

2021-05-3100:00:00
wpscan.com
7

0.001 Low

EPSS

Percentile

25.0%

In the plugin, the Custom CSS field of each gallery is not properly sanitised or validated before being being output in the page where the gallery is embed, leading to a stored Cross-Site Scripting issue.

PoC

Create or edit a gallery and add the following payload in the Custom CSS field:

CPENameOperatorVersion
foogallerylt2.0.35

0.001 Low

EPSS

Percentile

25.0%

Related for WPVDB-ID:950F46AE-4476-4969-863A-0E55752953B3